The Privacy Policy Permission Model: A Unified View of Privacy Policies

Maryam Majedi,Ken Barker
2024-03-26
Abstract:Organizations use privacy policies to communicate their data collection practices to their clients. A privacy policy is a set of statements that specifies how an organization gathers, uses, discloses, and maintains a client's data. However, most privacy policies lack a clear, complete explanation of how data providers' information is used. We propose a modeling methodology, called the Privacy Policy Permission Model (PPPM), that provides a uniform, easy-to-understand representation of privacy policies, which can accurately and clearly show how data is used within an organization's practice. Using this methodology, a privacy policy is captured as a diagram. The diagram is capable of highlighting inconsistencies and inaccuracies in the privacy policy. The methodology supports privacy officers in properly and clearly articulating an organization's privacy policy.
Cryptography and Security,Computers and Society
What problem does this paper attempt to address?
### Problems the Paper Attempts to Solve The paper aims to address the issue of privacy policies being difficult to understand. Specifically, most privacy policies are usually long, vague, and contain technical jargon, making it unclear how the information of data providers will be used. Additionally, organizations may aggregate data to generate new (correct or incorrect) knowledge about data providers. However, users often ignore these privacy policies because the process of interpreting them is very challenging, partly because they are written in natural language, which can easily lead to misunderstandings. These issues may result in illegal access permissions, further infringing on privacy. To address these problems, the authors propose a modeling method called the **Privacy Policy Permission Model (PPPM)**. This model can provide a unified and easy-to-understand representation of privacy policies, accurately and clearly demonstrating how data is used in organizational practices. Through this method, privacy policies can be captured as a chart that highlights inconsistencies and inaccuracies within the policies. This approach supports privacy officers in correctly and clearly articulating the organization's privacy policies.